Most scam websites give themselves away in under a minute — if you know the eight checks to run. This is the GACS checklist we drilled into every Safe Scanner result, condensed into a copy-paste workflow you can use on any URL right now.
The 60-second checklist
- Domain age. Type the domain into a WHOIS lookup or just run /check. Anything registered in the last 90 days that's also selling investments, crypto, or branded goods is a near-certain scam.
- Padlock means encrypted, not safe. Every scam site on the planet now has HTTPS. The padlock proves only that nobody can eavesdrop on your data being sent to the scammer.
- Brand vs. URL mismatch. Look at the URL letter by letter.
binance-pro.com,apple-icloud-id.net,paypal.secure-login.org— none of these belong to the brand they're imitating. Real brands use their bare domain. - Reverse-image search the hero photo. A 'team page' with stock photos or models lifted from another company is one of the strongest single signals.
- Check the Terms / About / Contact pages. Scam sites either copy the text verbatim from another site (Google a sentence in quotes), use the same Lorem-ipsum filler across multiple domains, or list a regulator licence number that doesn't validate when you look it up.
- Look for a withdrawal button that actually works. Fake brokers love showing 'profits' going up; they break at the moment you try to withdraw. If you can't find a clear, public withdrawal policy, walk away.
- Search the brand name + 'scam' or 'review'. Filter the date range to the last 12 months. One Reddit thread of victims is enough.
- Run [/safe-scanner](/safe-scanner). Paste the URL. GACS runs every check above plus our 250k-entity public blacklist, the WHOIS, the SSL cert, the on-chain signals if a wallet is referenced, and a content-classifier — in about four seconds, free, no signup.
The signals that almost always mean scam
- The site asks for a wallet seed phrase, ever.
- Live chat opens unsolicited within 10 seconds of landing.
- 'Account manager' assignment after deposit, especially via Telegram.
- 'Tax', 'commission', or 'clearance fee' demanded *before* a withdrawal.
- Domain registered through Namecheap / Hostinger / Tucows with privacy-shielded WHOIS, less than 6 months old, claiming an FCA / SEC / ASIC licence.
The signals that mean 'be careful', not 'scam'
- New domain but matches a real, registered company you can verify on Companies House / state-corp registry / VARA / SEC EDGAR.
- No HTTPS — old, neglected, probably not malicious. Don't enter payment details, but it's likely just abandoned.
- Bad English on an obviously foreign-language site — usually translation, not fraud.
What to do if you already paid
Open the Panic Guide. It walks you through the bank call, the screenshots, the report on GACS, and the country-specific authority report in one screen. Then read Recovery Scams before you accept any DM offering to 'get your funds back'.
FAQ — checking websites for scams
- *Is there a free Chrome extension that does this?* Yes — the GACS extension flags blacklisted sites and runs the Safe Scanner check inline, free.
- *Can I check a URL without clicking it?* Yes. Paste it into /check (or right-click → 'Check on GACS' if the extension is installed). The site is not opened.
- *Is a Trustpilot 5-star rating proof a site is safe?* No. Fake-review farms are cheap. Cross-check with at least one independent source — Reddit, GACS, or the regulator the site claims to be licensed by.
